Written and maintained by CASRAI Editorial Board
Last updated
A laboratory quality management system is the set of interacting processes that produce reliable results and keep evidence that they were produced correctly — document control, personnel competency, equipment calibration, method validation, internal audit, management review, and corrective action, all working on each other. A quality manual is one document inside that system: a scope statement and a map of how the processes interact. Building a QMS means building the processes themselves. Writing a manual is the much smaller, later step of describing them. See CASRAI’s quality manual guide for what belongs in that specific document once the system underneath it actually exists.
Which Framework Actually Applies to Your Lab
Most labs never pursue ISO 9001 certification directly, and that is not a gap — it is the normal, correct outcome. ISO 9001:2015 is a generic, sector-neutral quality management standard; the specific accreditation and regulatory frameworks that apply to laboratory work are built on the same architecture but add the technical content ISO 9001 deliberately leaves out. Which one applies depends on what the lab does with its results, not on lab size or budget:
- Testing or calibration work performed for external clients, where results carry legal or contractual weight — ISO/IEC 17025:2017 is the applicable framework. It is accreditation, not certification: a body such as A2LA or ANAB assesses the lab’s technical competence for a defined scope of tests, not the organization as a whole.
- Testing of human specimens for clinical or diagnostic use — ISO 15189:2022 applies outside the US (required for NHS pathology labs via UKAS, for example). Inside the US, CLIA (42 CFR Part 493) is the mandatory floor; CAP’s ISO 15189-based program or CAP’s own checklist accreditation can satisfy CLIA’s requirements through CMS deemed status.
- Nonclinical safety studies that will support a regulatory submission (toxicology, safety pharmacology) — Good Laboratory Practice under 21 CFR Part 58 applies, not a testing-accreditation standard. GLP is built around a named Study Director and an independent Quality Assurance Unit rather than a document-hierarchy audit.
- A quality-control lab sitting inside GMP-regulated manufacturing — the lab’s QMS is a subset of the site’s Pharmaceutical Quality System, structured around ICH Q10’s four management enablers (process/product monitoring, CAPA, change management, management review) layered on top of cGMP itself, not a standalone lab-specific standard.
A lab that does more than one of these things — a contract lab that is both ISO/IEC 17025-accredited for calibration work and runs GLP studies, for instance — runs two frameworks in parallel with a shared administrative backbone (document control, training records, equipment management) rather than picking one. The frameworks differ in technical content; the administrative processes underneath them are close to identical, which is exactly why building the system first, framework-agnostic, and then layering the framework-specific technical records on top is the more efficient build order.
The Process Approach: What ISO 9001 Contributes Even If You Never Certify to It
ISO/IEC 17025 and ISO 15189 both inherit their top-level structure from the same Annex SL high-level structure ISO 9001:2015 uses: context of the organization, leadership, planning, support (resources, competence, communication, documented information), operation, performance evaluation, and improvement. That is the “process approach” — managing the lab as a set of interrelated processes with defined inputs, outputs, and interactions, evaluated on a plan-do-check-act cycle, rather than as a pile of independent procedures. You do not need to certify to ISO 9001 to use its architecture; ISO 17025 and ISO 15189 already require it, using the same clause skeleton with laboratory-specific technical requirements substituted into the “operation” section.
In practice, building a lab QMS from the process approach up means identifying the processes first, then writing procedures for each one, not the reverse. A typical laboratory QMS process map includes:
- Sample or specimen management — receipt, chain of custody, storage, and disposition.
- Method selection and validation — including measurement uncertainty for testing/calibration work under ISO/IEC 17025.
- Equipment management — calibration, maintenance, and out-of-service handling; see CASRAI’s guides on reading a calibration certificate and qualifying an equipment or reagent vendor.
- Personnel competency — initial qualification, ongoing training records, and authorization to perform specific tests.
- Document and record control — versioning, approval, distribution, and retention.
- Internal audit — a planned, independent check that the system is being followed, distinct from an accreditation body’s external assessment.
- Management review — leadership periodically evaluates the system’s performance (audit results, complaints, corrective actions, proficiency-testing outcomes) and decides what changes.
- Nonconformity handling and corrective action (CAPA) — correcting a specific failure, then investigating and addressing its root cause so it doesn’t recur.
- Proficiency testing / external quality assessment — where applicable, an independent check on the lab’s actual result accuracy; see CASRAI’s PT/EQA guide.
Each process needs an owner, a written procedure, and records that demonstrate it actually happened — not just that it was written down. An auditor checking management review, for example, is checking for a dated record of what was reviewed and what was decided, not for a procedure describing how management review is supposed to work in principle.
The Document Hierarchy
Once the processes are identified, the document structure that supports them is normally built in four levels:
- Level 1 — Quality manual or quality policy. Scope, exclusions, and a description of how the processes interact. This is the single document CASRAI’s quality manual guide covers in detail. ISO 9001:2015 made this document optional; ISO/IEC 17025 and ISO 15189 do not require a standalone manual by that name, but most accredited labs keep an equivalent top-level document because assessors expect to see the scope-and-interactions summary somewhere.
- Level 2 — Procedures (SOPs). One per process identified above: how sample intake works, how internal audits are scheduled and conducted, how a nonconformity gets logged and closed.
- Level 3 — Work instructions and forms. Step-by-step detail for a specific test method or piece of equipment, plus the blank forms/templates used to generate records.
- Level 4 — Records. The completed forms, raw data, calibration certificates, training logs, and audit reports that prove the system operated as described. Records are evidence; procedures are instructions. Confusing the two — treating a well-written procedure as sufficient proof of compliance — is one of the most common findings in an accreditation assessment.
The Records Each Framework Adds on Top of the Common Core
The document-control, competency, and internal-audit records above are common to essentially every framework. Each specific standard then requires its own additional technical records:
- ISO/IEC 17025:2017 adds: technical records for each test/calibration (raw data sufficient to reconstruct the result), measurement uncertainty evaluations, equipment calibration status linked to traceability, and documented evidence of impartiality and risk-based thinking applied to the lab’s operations.
- ISO 15189:2022 adds: records structured around the pre-examination, examination, and post-examination phases of the testing pathway, point-of-care testing (POCT) oversight records where applicable, and patient-safety/incident records specific to clinical result reporting.
- GLP (21 CFR Part 58) adds: the study protocol and any amendments, Study Director sign-off, Quality Assurance Unit inspection records kept independent of the study team, and raw data retained for the full study-archive period rather than a routine document-retention schedule.
- GxP / ICH Q10 quality-control labs adds: batch/lot-linked testing records, data-integrity controls consistent with ALCOA+ principles, and CAPA records that roll up into the site’s broader Pharmaceutical Quality System rather than standing alone at the lab level.
A lab building its QMS for the first time gets the biggest return on effort by building the common core well — document control, competency records, internal audit, management review, CAPA — before layering on framework-specific technical records. The common core is what most of the system actually consists of by volume; the framework-specific additions are comparatively small once the underlying process infrastructure exists.
Frequently Asked Questions
Does a laboratory need ISO 9001 certification to have a quality management system?
No. Most labs build their QMS around ISO/IEC 17025, ISO 15189, GLP, or a GxP-derived framework instead — each already incorporates the same process-approach architecture ISO 9001 defines, with laboratory-specific technical requirements added. ISO 9001 certification adds cost and an additional audit cycle without adding a requirement the applicable laboratory framework doesn’t already cover.
What’s the difference between a quality management system and a quality manual?
The QMS is the full set of processes, procedures, and records that actually govern how the lab operates. The quality manual is one Level 1 document that summarizes the system’s scope and describes how its processes interact — a map of the system, not the system itself. A lab can have a well-written manual and a nonfunctional system underneath it, which is exactly what an accreditation assessment is designed to catch.
How many procedures does a lab QMS actually need?
One per process the lab actually has, not a fixed number set by the standard. A small single-scope calibration lab might operate with a dozen core SOPs; a multi-department clinical lab with several accredited test menus will have substantially more. The right count follows from the process map, not from a template borrowed from a larger or differently-scoped lab.
Can a lab be accredited to more than one framework at once?
Yes, and it’s common for contract and reference labs — for example, ISO/IEC 17025 accreditation for calibration services alongside GLP status for nonclinical studies. The administrative backbone (document control, training records, equipment management, internal audit, management review) is normally shared across both; only the technical requirements and records layered on top differ by framework.
Related reading: Quality Manual for a Regulated Organisation · ISO/IEC 17025 Explained · ISO 15189 Accreditation · Good Laboratory Practice (GLP) · CLIA Quality Control Requirements · Proficiency Testing & EQA








